HoneyBOT is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Brim, NetworkMiner, Wireshark, Libemu (sctest), scdbg, IP LookUp, Initial Access, Execution, Privilege Escalation, Stealth, Command and Control.
Reconstruct a network intrusion by analyzing PCAP traffic with Wireshark, identifying a CVE-2003-0533 exploit, extracting malware, and performing shellcode analysis with scdbg to uncover attacker techniques and IOCs.
Categories: Network Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Privilege Escalation, Stealth, Command and Control.
Tools: Brim, NetworkMiner, Wireshark, Libemu (sctest), scdbg, IP LookUp.
Difficulty: medium.